Live Feed/GitLab/Fact Record
GitLab logo
GitLab
feature 96% Confidence Gate September 17, 2026

GitLab 19.4 release notes

GitLab 19.4 introduces centralized governance for MCP server tools and expands Advanced SAST to include Kotlin, Dart, and Scala. The release also adds support for SPDX license expressions in dependency and license scanning.

Verified State Diff

Comparison Mode:
- Previous State
MCP server tools followed fixed, unchangeable governance rules; Advanced SAST lacked support for Kotlin, Dart, and Scala; SPDX composite licenses were reported as 'unknown' and excluded from approval policies.
+ Verified New State
MCP server tools are configurable via group/project settings; Advanced SAST provides deep taint analysis for Kotlin, Dart, and Scala; SPDX license expressions are fully parsed and supported in approval policies.

Impact & Verification Analysis

WHO IS AFFECTED

Enterprise security teams, DevOps engineers, and developers working with Kotlin, Dart, or Scala codebases.

WHY IT MATTERS

This release significantly reduces the attack surface for AI-driven automation and improves compliance accuracy by enabling precise policy enforcement for complex open-source licensing and modern language frameworks.

Full Fact Overview

GitLab 19.4 expands the control plane for AI agents by allowing governance of third-party MCP server tools alongside internal Duo Agent Platform tools, enabling granular 'Always Allow' or 'Always Ask' policies. The Advanced SAST engine has been upgraded to support Kotlin (Android APIs), Dart (Flutter/Dio), and Scala (Play/Slick/Akka) using deep taint analysis. Additionally, the dependency scanning engine now parses SPDX license expressions, enabling automated policy enforcement for complex, multi-license dependencies that were previously categorized as 'unknown'.

Multi-Source Evidence Chain (1)

GitLab 19.4 release notesGitLab
TRACKED ENTITY
Explore all historical GitLab changes
View GitLab Hub ➔